VYPR
High severity8.5NVD Advisory· Published Jul 4, 2025· Updated Apr 23, 2026

CVE-2025-30947

CVE-2025-30947

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade popup cool-fade-popup allows Blind SQL Injection.This issue affects Cool fade popup: from n/a through <= 10.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Blind SQL injection in Cool fade popup WordPress plugin (≤10.1) allows unauthenticated attackers to steal database contents.

Vulnerability

Overview

The Cool fade popup WordPress plugin (versions up to and including 10.1) contains a blind SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This flaw arises from insufficient input validation and sanitization before user-supplied data is incorporated into database queries [1].

Exploitation

Details

An unauthenticated attacker can exploit this vulnerability remotely by sending crafted requests to the affected plugin. Since the SQL injection is blind, the attacker does not receive direct error messages but can infer information from the application's response behavior. The official advisory categorizes this vulnerability as High severity with a CVSS v3 score of 8.5 [1].

Impact

Successful exploitation allows an attacker to interact directly with the WordPress database behind the affected site. This could lead to the extraction of sensitive information, including user credentials, personal data, and other stored content. The advisory notes that such vulnerabilities are often used in mass-exploit campaigns targeting thousands of websites regardless of size or popularity [1].

Mitigation

Status

Users are strongly advised to immediately update the plugin to a patched version (beyond 10.1) if available. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended. No workaround other than updating has been documented in the advisory [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.